nix: give the gateway, resolver and bridge their own enable
`services.hyperhive.gateway.enable`, `gateway.dns.enable` and `network.enable` replace the `hyperhive.enable` gate on all three. Each defaults to false; the modules that need one assert it with `mkDefault true` from inside the guard their own deployment already carries, and `swarm-required-services.nix` — the module that owns what the swarm-services toggle implies — asserts all three explicitly. hive-c0re asserts all three unconditionally, so an ordinary hive keeps getting them with no opt-in: it is the host's only knowledge that agent containers exist. The resolver moves to its own `hive-gateway/dns.nix` so it can be gated without reindenting the nginx half of the module. Reinstates `network.enable`, dropping its `mkRemovedOptionModule` shim. A config still carrying `network.enable = false` from before the removal now switches the bridge off instead of failing eval. Also deletes a duplicate `centralToggleOff` fixture in nix/module-eval.nix. Two sibling slices added it independently (c5f60fd5,ce3b3d94); the merge was textually clean and left `main` failing to evaluate at all, so this file could not be gated without removing one.
This commit is contained in:
parent
a4e4016214
commit
d8e26a17bb
21 changed files with 249 additions and 75 deletions
|
|
@ -87,6 +87,18 @@ in
|
|||
# hive that is not the service host is a *client* of it, not a second one.
|
||||
config.services.hyperhive.deploy.victorialogs.enable = lib.mkDefault deployCfg.allSwarmServices;
|
||||
|
||||
# The plumbing those services are reached over: every one of them is
|
||||
# fronted by the gateway, resolved through the hive's dnsmasq, and runs
|
||||
# in a container hanging off the bridge. Written as `mkIf … mkDefault`
|
||||
# rather than `mkDefault allSwarmServices` because the modules that need
|
||||
# these also assert them — a `false` from here would collide with their
|
||||
# `true` instead of losing to it.
|
||||
config.services.hyperhive.gateway.enable = lib.mkIf deployCfg.allSwarmServices (lib.mkDefault true);
|
||||
config.services.hyperhive.gateway.dns.enable = lib.mkIf deployCfg.allSwarmServices (
|
||||
lib.mkDefault true
|
||||
);
|
||||
config.services.hyperhive.network.enable = lib.mkIf deployCfg.allSwarmServices (lib.mkDefault true);
|
||||
|
||||
# The secret store. Once per swarm and optional, so it belongs to the
|
||||
# same switch: a hive that does not run it is a *client*, reading its
|
||||
# own secrets from whoever does. `mkDefault` is what keeps the store
|
||||
|
|
|
|||
Loading…
Reference in a new issue